High severity7.1NVD Advisory· Published Aug 11, 2026· Updated Sep 16, 2026
CVE-2026-18687
CVE-2026-18687
Description
MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request parameters against the collection's encrypted field configuration before use. An authenticated user with readWrite privileges could submit a specially formed request that leads to a server crash or excessive internal writes, resulting in resource exhaustion and corruption of encrypted index data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
1- jira.mongodb.org/browse/SERVER-130628nvdVendor Advisory
News mentions
1- MongoDB Server: Thirteen Vulnerabilities Disclosed in Single BatchVypr Intelligence · Aug 11, 2026